OBL-01Obligations and Compliance

Obligation inventory

Legal, regulatory and contractual obligations that apply are identified, owned and kept current.

Why it exists

You cannot meet an obligation you have not written down.

What usually proves it

Obligation register with source, owner and evidence link.

Smaller organizations

One register, reviewed when a contract or law changes.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC2.3
  • Fully addressedISO/IEC 27001 Annex A · A.5.31
  • Fully addressedNIST Cybersecurity Framework · GV.OC-03
  • Partially addressedPCI DSS · 12.1 — Scoped to PCI DSS obligations.
  • Partially addressedHIPAA Security Rule · 164.316 — Documentation duty rather than an inventory.
  • Partially addressedGDPR · Art. 30 — Records of processing rather than obligations.
  • Partially addressedEU AI Act · Art. 16 — Provider obligations are enumerated by the Act itself.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 1.1